CVE-2025-39711
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39711 is a vulnerability discovered in the Linux kernel's media subsystem, specifically in the Intel Virtual Sensor Camera (IVSC) driver. The vulnerability was disclosed on September 5, 2025, affecting the ACE and CSI drivers which were missing mei_cldev_disable() calls in their remove() functions (NVD).

Technical details

The vulnerability stems from a missing mei_cldev_disable() call in both the ACE and CSI driver remove() functions. This causes the mei_cl client to remain part of the mei_device->file_list list even after its memory is freed by mei_cl_bus_dev_release() calling kfree(cldev->cl). The issue manifests as a use-after-free condition when mei_vsc_remove() executes mei_stop(), which first removes all mei bus devices by calling mei_ace_remove() and mei_csi_remove(), followed by mei_cl_bus_dev_release(), and then calls mei_cl_all_disconnect() which attempts to access the already freed cldev->cl (NVD).

Impact

The vulnerability leads to a use-after-free condition that can cause system crashes during shutdown. This was confirmed through KASAN (Kernel Address Sanitizer) reports showing memory access violations. The issue specifically occurs when the system is shutting down due to the platform_device_unregister(tp->pdev) call in vsc_tp_shutdown() (NVD).

Mitigation and workarounds

The fix involves adding the missing mei_cldev_disable() calls to ensure that the mei_cl is properly removed from mei_device->file_list before it is freed. This prevents the use-after-free condition from occurring (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management